A deep dive on pitches to governments from cyber-intel firms like Cellebrite, NSO Group, and Intellexa to use their spy tools to trace the coronavirus
Context & Ripple Effects
Reuters' deep dive lands weeks after NSO Group began marketing mobile-data software to monitor and predict COVID-19's spread, and the pitch has since widened to Cellebrite and Intellexa — firms whose core business is government hacking and interception, now repackaged as pandemic response. The sales angle matters because these vendors sell almost exclusively to states, as Intellexa's founder confirmed while denying any non-state customers.
The arc runs through Toronto's Citizen Lab, whose researchers have spent years exposing this industry — including meetings they say were staged to extract compromising quotes — and later found Pegasus on a device inside UK No. 10. The question Reuters raises is whether an emergency gives surveillance vendors their most legitimate-sounding market yet.
First-order effects
- Governments weighing contact-tracing contracts get a new class of bidder: firms like Cellebrite, NSO Group, and Intellexa offering phone-location and interception tooling under public-health framing.
Second-order effects
- NSO's own conduct during the pitch cycle — researchers found it used location data from thousands of unsuspecting people while courting buyers — hands civil-society critics like Citizen Lab fresh evidence that pandemic framing expands surveillance rather than containing disease.
Third-order effects
- US sanctions on NSO have not slowed the sector — investigations show government spyware use booming anyway, including the DEA's secret Graphite deployment — suggesting health emergencies become procurement cover that outlasts the crisis itself.
The trend: Commercial spyware vendors are using each public emergency as a licensing opportunity, with state demand proving resilient even to sanctions and exposés.